dragoncitygames[.]com
“Dragon City”
Gespeicherte Beobachtung
Beobachteter Titelkontrast
Zusammenfassung der Beweislage
This domain, dragoncitygames.com, operates as a credential harvesting platform specifically targeting users of a major cryptocurrency exchange. Analysis indicates the site presents a fraudulent interface mimicking the legitimate exchange's login and authentication workflows, designed to capture sensitive account credentials, two-factor authentication codes, and recovery phrases. The page title 'Dragon City' serves as a weak obfuscation attempt, while the underlying infrastructure and content structure align with known exchange impersonation tactics observed in prior campaigns. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain resolves to 172.66.0.70, hosted on Cloudflare's AS13335 network, a common evasion tactic to conceal origin servers. Registered through GoDaddy.com, LLC on December 29, 2025, the domain remains unencrypted with no SSL certificate present. Detection metrics show 13 of 95 security engines on VirusTotal flagging the domain as malicious, while three distinct security blocklists have incorporated it into their threat feeds. Additional automated systems have independently classified this as a brand impersonation threat, with confirmed blocking by multiple domain reputation services. Users who accessed dragoncitygames.com or entered credentials on any page resembling the targeted exchange interface should immediately revoke active sessions and rotate all authentication factors. Monitor associated accounts for unauthorized transactions or configuration changes, particularly those involving withdrawal addresses or API key generation. If cryptocurrency transfers were initiated, document all transaction hashes and contact the legitimate exchange's security team with the collected evidence. Network administrators should add the domain and associated IP 172.66.0.70 to internal blocklists to prevent further exposure within organizational environments.
Data Coverage
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 11.08.2026
Erkennungszeitleiste
-
VirusTotal
13 → 14
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt